Skip to content

fix(client/auth): tolerate comma-separated scope strings - #3568

Closed
dgilman-perplexity wants to merge 1 commit into
modelcontextprotocol:mainfrom
dgilman-perplexity:fix/comma-separated-scopes
Closed

dgilman-perplexity wants to merge 1 commit into
modelcontextprotocol:mainfrom
dgilman-perplexity:fix/comma-separated-scopes

Conversation

@dgilman-perplexity

@dgilman-perplexity dgilman-perplexity commented Sep 23, 2026

Copy link
Copy Markdown

Fixes #3566.

Motivation

RFC 6749 §3.3 separates scopes with spaces, but real-world authorization servers (e.g. Linear) return comma-separated scope values in token responses and WWW-Authenticate challenges. Scope membership checks and the SEP-2350 step-up union split on whitespace only, so a comma-separated grant is treated as a single opaque scope: unions stop deduplicating (scopes accumulate as read,write read write) and offline_access/prompt=consent handling misfires.

Change

Adds a parse_scopes helper that accepts both space and comma separators and uses it in union_scopes and the two offline_access membership checks. The join side is unchanged — the client always emits space-separated scope strings. Parametrized tests for the helper and a comma-input case for union_scopes included.

🤖 Generated with Claude Code

RFC 6749 §3.3 separates scopes with spaces, but real-world authorization
servers (e.g. Linear) return comma-separated scope lists in token
responses and WWW-Authenticate challenges. Scope membership checks and
the SEP-2350 step-up union split on whitespace only, so a
comma-separated grant is treated as a single opaque scope: unions stop
deduplicating and offline_access handling misfires.

Add a parse_scopes helper accepting both separators and use it in
union_scopes and the offline_access membership checks.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 23, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. It's still a draft, but we close those early so you don't put in more time only to have it closed the moment you mark it ready.

This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3566.

If a maintainer assigns you to #3566, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

@github-actions github-actions Bot closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OAuth client scope handling breaks on comma-separated scope strings

1 participant